Avaya BCM 4.0 Networking Przewodnik Konfiguracji Strona 677

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 758
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 676
Chapter 68 Virtual Private Networks (VPN) 677
BCM 4.0 Networking Configuration Guide
Split Tunneling security considerations
BCM takes precautions against violators potentially hacking tunneled information when the BCM
is operating in Split Tunnel mode.
The primary precaution is to drop packets that do not have the IP address that is assigned to the
tunnel connection as its source address. For example, if you have a PPP dial-up connection to the
Internet with an IP address of 192.168.21.3, and you set up an IPSec client connection to a BCM
and you are assigned an IPSec client IP address of 192.192.192.192, then any packets that attempt
to pass through the IPSec client tunnel connection with a source IP address of 192.168.21.3 (or any
address other than 192.192.192.192) will be dropped.
Adding a Remote User IPSec Tunnel
A Remote User IPSec Tunnel connects a remote computer to the BCM system.
Assigning an IP Address to a Remote User Account
The Remote User tunnel requires that an IP address is assigned to the Remote User when they log
into the BCM. This IP address must be in the private IP network that the Remote User is able to
access.
The BCM supports two methods of assigning an IP Address to the Remote User Tunnel. You can
use a static IP address or a dynamic IP address from an IP Address Pool.
Static IP Address
To assign a static IP address to the Remote User account, you must configure the following two
options when you configure the Remote User Tunnel settings:
Static IP Address
Subnet Mask
Note: To completely eliminate security risks, you should not use the Split
Tunneling feature.
Note: The remote computer must have the VPN Client installed.
Note: If the computer running the VPN client is not on the same subnet as the Destination
address (i.e. there is at least one router between the computer and the BCM), then the
default Next Hop Router on the BCM must also be through this interface. For instructions
on setting up a default Next Hop Router, refer to “Configuring Net Link Manager” on
page 567.
Przeglądanie stron 676
1 2 ... 672 673 674 675 676 677 678 679 680 681 682 ... 757 758

Komentarze do niniejszej Instrukcji

Brak uwag